Vulnerability index

Browse CVEs

73 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Sharepoint Server HIGH 8.8
CVE-2026-62827

Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Fix: 16.0.19725.20522+
Fix from $4,900 2026-08-11
Teams CRITICAL 9.6
CVE-2026-62896

Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-08-07
Azure Sql Database CRITICAL 10.0
CVE-2026-56162

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-08-07
Azure Key Vault CRITICAL 9.8
CVE-2026-62825

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-24
Exchange Online CRITICAL 10.0
CVE-2026-56191

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

No fix yet
Fix from $2,300 2026-07-24
Windows 10 1607 HIGH 8.0
CVE-2026-50365

Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows Admin Center HIGH 8.8
CVE-2026-56169

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

Fix: 2606+
Fix from $1,950 2026-07-14
Windows Admin Center HIGH 7.8
CVE-2026-57107

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.

Fix: 2606+
Fix from $1,950 2026-07-14
Windows Admin Center MEDIUM 6.5
CVE-2026-56185

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

Fix: 2511+
Fix from $1,600 2026-07-14
Azure Spring Cloud HIGH 8.2
CVE-2026-50338

Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.

Fix: 7.3.0+
Fix from $1,950 2026-07-14
Azure Active Directory CRITICAL 10.0
CVE-2026-45480

Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-06-19
Azure Ai Bot Service HIGH 8.8
CVE-2026-32174

Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-06-18
Windows 11 23h2 HIGH 7.8
CVE-2026-44810

Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.20348.5256 / 10.0.22631.7219+
Fix from $1,950 2026-06-09
Azure Resource Manager CRITICAL 9.8
CVE-2026-47280

Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-05-22
Azure Local CRITICAL 10.0
CVE-2026-42822

Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.

Fix: 2604.2.25645+
Fix from $2,300 2026-05-18
Azure Sdk For Java CRITICAL 9.1
CVE-2026-33117

The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag com…

Fix: 4.10.6+
Fix from $2,300 2026-05-12
Windows 10 1607 MEDIUM 6.2
CVE-2026-32072

Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,600 2026-04-14
Azure Sre Agent HIGH 7.5
CVE-2026-32173

Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-04-03
Azure Automation Hybrid Worker Windows Extension HIGH 7.8
CVE-2026-26141

Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

Fix: 1.3.74+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.8
CVE-2026-26128

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.8
CVE-2026-24294

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows Admin Center HIGH 8.8
CVE-2026-26119

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

Fix: 2511+
Fix from $1,950 2026-02-17
Windows 10 1607 HIGH 7.0
CVE-2026-21508

Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 10 21h2 HIGH 7.0
CVE-2025-55340

Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.19044.6456 / 10.0.19045.6456+
Fix from $1,950 2025-10-14
Windows 10 1507 CRITICAL 9.8
CVE-2025-55234EPSS 20%

SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could p…

Fix: 10.0.10240.21128 / 10.0.14393.8422+
Fix from $2,300 2025-09-09
Windows 10 1507 HIGH 8.8
CVE-2025-54918EPSS 19%

Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.10240.21128 / 10.0.14393.8422+
Fix from $1,950 2025-09-09
Entra Id CRITICAL 10.0
CVE-2025-55241

Azure Entra ID Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-09-04
Azure Stack Hub HIGH 7.5
CVE-2025-53793

Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.

Fix: 1.2406.1.23 / 1.2408.1.50+
Fix from $1,950 2025-08-12
Windows 10 1507 HIGH 8.8
CVE-2025-53778EPSS 38%

Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.10240.21100 / 10.0.14393.8330+
Fix from $1,950 2025-08-12
Exchange Server HIGH 8.0
CVE-2025-53786EPSS 7%

On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made…

Fix: 15.02.2562.017+
Fix from $1,950 2025-08-06